Privacy Policy

Last updated 23 September 2026

1.0Introduction

1.1 About this Policy

This Privacy Policy explains how the operator of the MIHAS platform ("we," "us," or "our") collects, uses, discloses, and protects personal data when you register for, attend, exhibit at, or otherwise take part in the Malaysia International Halal Showcase ("MIHAS") through our websites, portals, and related services (collectively, the "Platform").

This Policy is issued in accordance with the Personal Data Protection Act 2010 of Malaysia ("PDPA") and forms part of our Terms of Use. Terms defined in the Terms of Use have the same meaning here.

1.2 Who this Policy Applies to

This Policy applies to every person whose personal data is processed through the Platform, including trade and public visitors, exhibitors and their representatives, hosted buyers, VIP guests, award participants, media representatives, speakers, and newsletter subscribers.

1.3 Your Consent

By registering on, signing in to, or otherwise using the Platform, you consent to the processing of your personal data as described in this Policy. Where you give us personal data about another person (for example, a colleague you register as a representative), you confirm that you have their consent to do so and have made this Policy available to them.

2.0Personal Data We Collect

2.1 Information You Provide

Depending on how you take part in MIHAS, we may collect:

  • Identity and contact details: name, salutation, gender, job title or designation, email address, mobile and office telephone numbers, postal address, and country
  • Account details: sign-in email, password (stored only in hashed form), preferred language, and profile photograph
  • Business information: company name, company registration number, organisation type, industry, sectors, products and services of interest, purpose of visit, company size and turnover band, and business ownership information (such as Bumiputera, SME, or women-owned status) used for national trade statistics
  • Identification documents: identity card or passport number, where required to issue an exhibitor or representative badge
  • Participation details: hosted buyer applications, VIP nominations and questionnaires, media accreditation requests, award submissions, programme and seminar registrations, meeting requests, and feedback survey responses
  • Communications: messages exchanged with other participants through the Platform, support tickets, and any files you attach to them

2.2 Information Collected Automatically

  • Sign-in records: the date and time of each sign-in, IP address, and browser or device type
  • Venue activity: badge or QR pass scans at entrances, halls, seminars, and exhibitor booths, with the time and location of each scan
  • Platform activity: exhibitors and programmes you save or bookmark, searches, and meetings you book or attend
  • Device information: if you enable browser notifications, the notification address your browser gives us

2.3 Information from Other Sources

We may receive personal data about you from:

  • An exhibitor or company that registers you as its representative or nominates you as a VIP guest
  • The organiser of MIHAS and its appointed agencies, where you are invited as a hosted buyer, VIP, speaker, or award participant
  • Our registration and badging partners, where you registered through their systems

2.4 Obligatory and Voluntary Information

Fields marked as required on our forms are obligatory. If you do not provide them, we may be unable to register you, issue your pass or badge, or provide the Service you requested. All other information is voluntary.

3.0How We Use Your Personal Data

We process personal data for the following purposes:

  • Registering you for MIHAS and creating and managing your account
  • Issuing visitor passes, badges, and QR entry codes, and verifying them at the venue
  • Processing hosted buyer, VIP, media, award, and programme applications
  • Arranging business matching and meetings between buyers and exhibitors
  • Enabling exhibitors to record leads when you visit their booths and choose to share your details
  • Sending you transactional messages about your registration, meetings, and participation
  • Sending you event newsletters and updates, where you have not opted out
  • Responding to your enquiries and support requests
  • Compiling trade and attendance statistics for reporting by the organiser, in aggregated form wherever possible
  • Maintaining the security of the Platform and the venue, and preventing fraud and misuse
  • Complying with legal and regulatory obligations

We do not sell your personal data.

4.0AI and Automated Processing

4.1 How We Use AI

Some features of the Platform use artificial intelligence services to suggest relevant exhibitors, recommend business meetings, summarise company profiles, classify products, and translate messages. To do this, we send the relevant business information (such as company name, industry, products, and stated interests) to our AI service providers described in Section 6.0. The text of a message is sent only when you ask the Platform to translate it.

4.2 Your Decisions Remain Yours

AI outputs are suggestions only. They do not make decisions that have legal or similarly significant effects on you, and a meeting or match only proceeds when you or the organiser accept it. We do not send passwords or identity card and passport numbers to AI services.

5.0Emails and Communications

5.1 Transactional Messages

While you are registered, we will send you messages that are necessary for your participation, such as registration confirmations, passes and badges, meeting invitations, sign-in codes, and replies to your support requests. These messages cannot be switched off while your registration is active.

5.2 Newsletters and Event Updates

We may send you newsletters and updates about MIHAS and related trade events. Every such email contains an unsubscribe link that takes effect without requiring you to sign in. You may also opt out at any time by contacting us using the details in Section 14.0.

6.0Disclosure of Personal Data

We disclose personal data only to the following classes of parties, and only as far as necessary for the purposes in Section 3.0:

  • The organiser of MIHAS and the government agencies and appointed partners that work with it to run the event and report on trade outcomes
  • Other participants: when you book a meeting, exchange messages, or allow your badge to be scanned at a booth, the exhibitor or buyer concerned receives your name, company, job title, and contact details
  • Service providers that process data on our behalf under contract, namely cloud hosting and file storage (DigitalOcean), email delivery (Mailgun), AI services (currently OpenAI and DeepSeek), and our registration and badging partners
  • Authorities, where disclosure is required or permitted by law, or is necessary to protect the safety of attendees or the security of the Platform

7.0Transfers Outside Malaysia

Our servers are located in Singapore, and some of our service providers process data in other countries, including the United States. We transfer personal data outside Malaysia only in accordance with Section 129 of the PDPA, to places with laws substantially similar to the PDPA or where we have taken reasonable steps to ensure that the data receives a comparable level of protection.

8.0Cookies

The Platform uses only the cookies it needs to work: a session cookie that keeps you signed in, a security token that protects forms from forgery, and a record of your preferred language. We do not use advertising cookies or third-party analytics trackers.

You can block cookies in your browser settings, but you will not be able to sign in to the Platform without them.

9.0Data Security

We take practical steps to protect personal data from loss, misuse, and unauthorised access, modification, or disclosure, including:

  • Encrypting data in transit with TLS
  • Storing passwords only in hashed form
  • Restricting staff access by role, and logging administrative actions
  • Using signed links for sign-in, invitations, and unsubscribes, so that they cannot be guessed or altered

No system is completely secure. If a data breach occurs that is likely to cause you significant harm, we will notify you and the relevant authorities as required by law.

10.0Retention

We keep personal data only for as long as necessary to fulfil the purposes in this Policy, including running future editions of MIHAS where you have registered with us before, and to meet legal, regulatory, and reporting requirements. When personal data is no longer needed, we delete it or anonymise it so that it can no longer identify you. Aggregated statistics that do not identify you may be kept indefinitely.

11.0Your Rights

Subject to the PDPA, you have the right to:

  • Access the personal data we hold about you
  • Correct personal data that is inaccurate, incomplete, misleading, or out of date. You can update most of your details yourself from your profile
  • Withdraw your consent to the processing of your personal data, in whole or in part
  • Object to processing that is likely to cause you substantial damage or distress
  • Stop direct marketing, by using the unsubscribe link in any newsletter or by contacting us
  • Data portability: request that your personal data be sent to another data controller, where technically feasible

To exercise these rights, please contact us using the details in Section 14.0. We will respond within twenty-one (21) days, as required by the PDPA, and may charge the fee the PDPA permits for access requests. If you withdraw your consent, we may be unable to continue providing some or all of the Services to you.

12.0Minors

The Platform is intended for business and trade participants. If you are under the age of eighteen (18), you may only register with the consent of your parent or guardian, who is responsible for the personal data you provide.

13.0Changes to this Policy

We may update this Policy from time to time. The date at the top of this page shows when it was last changed. We will notify you of material changes by email or through the Platform, as described in the Terms of Use.

14.0Contact Information

14.1 Data Protection Enquiries

For requests or complaints about your personal data, or to contact our Data Protection Officer:

14.2 General Support

For questions about your registration or account:

END OF PRIVACY POLICY This Privacy Policy was last updated on September 23, 2026.